Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

39 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.3%—Totolink Lr1200gb Firmware16/1/202417/6/2026
A vulnerability, which was classified as critical, was found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument pppoeUser leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has…
ModificadaCrítica (9.8)1.3%—Totolink Lr1200gb Firmware16/1/202417/6/2026
A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. This issue affects the function setSmsCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument text leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has…
ModificadaCrítica (9.8)3.8%—Totolink Lr1200gb Firmware8/1/202417/6/2026
A vulnerability, which was classified as critical, was found in Totolink LR1200GB 9.1.0u.6619_B20230130. This affects the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument hostName leads to os command injection. It is possible to initiate the attack remotely. The exploit has been…
ModificadaCrítica (9.8)3.8%—Totolink Lr1200gb Firmware8/1/202417/6/2026
A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this issue is the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to os command injection. The attack may be launched remotely. The exploit has been…
ModificadaCrítica (9.8)4.8%—Totolink Lr1200gb Firmware8/1/202417/6/2026
A vulnerability classified as critical was found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this vulnerability is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to os command injection. The attack can be launched remotely. The exploit has…
ModificadaCrítica (9.8)4.9%—Totolink Lr1200gb Firmware8/1/202417/6/2026
A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument hostName leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed…
ModificadaAlta (8.8)4.4%—Totolink Lr1200gb Firmware8/1/202417/6/2026
A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been rated as critical. This issue affects the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to command injection. The attack may be initiated remotely. The exploit has been…
ModificadaMedia (6.5)0.18%—Mediatek Lr12aMediatek Nr15Mediatek Nr16Mediatek Nr176/11/202317/6/2026
In modem CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction may be also needed for exploitation Patch ID: MOLY01138425; Issue ID: MOLY01138425 (MSV-862).
ModificadaCrítica (9.8)8.7%—Totolink Lr1200gb Firmware31/10/202317/6/2026
TOTOLINK LR1200GB V9.1.0u.6619_B20230130 was discovered to contain a stack overflow via the password parameter in the function loginAuth.
ModificadaCrítica (9.8)0.68%—Mediatek Lr11Mediatek Lr12aMediatek Lr13Mediatek Nr15+22/10/202317/6/2026
In CDMA PPP protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: MOLY01068234; Issue ID: ALPS08010003.
ModificadaAlta (7.5)1.1%—Mediatek Lr12aMediatek Lr13Mediatek Nr15Mediatek Nr168/11/202217/6/2026
In Modem 4G RRC, there is a possible system crash due to improper input validation. This could lead to remote denial of service, when concatenating improper SIB12 (CMAS message), with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00867883; Issue ID:…
ModificadaCrítica (9.8)3.4%—Mediatek Lr11Mediatek Lr12Mediatek Lr12aMediatek Lr13+36/7/202217/6/2026
In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding GPRS Packet Neighbour Cell Data (PNCD) improper neighbouring cell size with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
ModificadaCrítica (9.8)2.8%—Mediatek Lr11Mediatek Lr12Mediatek Lr12aMediatek Lr13+36/7/202217/6/2026
In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding combined FACILITY with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00803883; Issue ID: MOLY00803883.
ModificadaAlta (7.5)0.74%—Mediatek L9Mediatek Lr11Mediatek Lr12Mediatek Lr12a+24/1/202217/6/2026
In Modem EMM, there is a possible information disclosure due to a missing data encryption. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00716585; Issue ID: ALPS05886933.
Orbitaley — Vulnerabilidades